SEC: fix security breaches in GHA workflows detected with zizmor#17315
Conversation
|
Thank you for your contribution to Astropy! 🌌 This checklist is meant to remind the package maintainers who will review this pull request of some common things to look for.
|
|
👋 Thank you for your draft pull request! Do you know that you can use |
fdd7f82 to
6f819a8
Compare
Well, not like I did it for fun. We need extra access to post comment on PR. Will the zizmor dev able to give advice? |
There was a problem hiding this comment.
Not really a way to check this on PR but I can probably do a trigger after merge if necessary.
|
Apparently he's very reactive yes. So I heard. |
|
Do we want to add this to the pre-commit? https://github.com/woodruffw/zizmor/blob/a3e84e6564e6025ce4c5e7bb3ab024d5dbf62901/docs/usage.md?plain=1#L106-L130 |
Is that necessary? We do not add new workflows often. |
Is that good or bad? 😅 |
oooh I didn't see there was a pre-commit hook already.
Sure, but zizmor might add new checks in the future (the tool is extremely new), that we might want to know about sooner rather than later.
good ! |
|
zizmor 0.6 now supports |
|
I guess doesn't hurt... |
6f819a8 to
a04f23c
Compare
WilliamJamieson
left a comment
There was a problem hiding this comment.
This seems reasonable to me.
|
pre-commit.ci is having issues building zizmor 0.6.0 (and I have to confess I did to; I needed to update |
a04f23c to
e1357a3
Compare
pllim
left a comment
There was a problem hiding this comment.
Thanks!
If you want, feel free to open follow up issue for the pre-commit.
|
Owee, I'm MrMeeseeks, Look at me. There seem to be a conflict, please backport manually. Here are approximate instructions:
And apply the correct labels and milestones. Congratulations — you did some good work! Hopefully your backport PR will be tested by the continuous integration and merged soon! Remember to remove the If these instructions are inaccurate, feel free to suggest an improvement. |
|
@neutrinoceros backport would be nice but not critical, so if you don't feel like manual backporting, feel free to change milestone. Thanks! |
|
I'll try a manual backport tomorrow ! |
…s detected with zizmor SEC: fix security breaches in GHA workflows detected with zizmor (cherry picked from commit 803c7bd)
…s detected with zizmor SEC: fix security breaches in GHA workflows detected with zizmor (cherry picked from commit 803c7bd)
Backport PR #17315 on branch v7.0.x (SEC: fix security breaches in GHA workflows detected with zizmor)
Description
This fixes a couple security issues I found using
zizmor.One more issue remains unadressed because I do not understand what the problem is or how to address it. Here's the current output: